First published: Thu Apr 03 2025(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Social Share And Social Locker allows Blind SQL Injection. This issue affects Social Share And Social Locker: from n/a through 1.4.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Social Share And Social Locker | <=1.4.2 | |
WordPress Social Share And Social Locker Plugin | <=1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31911 has a high severity level due to its potential to allow blind SQL injection.
To fix CVE-2025-31911, update the NotFound Social Share And Social Locker plugin to version 1.4.3 or later.
CVE-2025-31911 affects NotFound Social Share And Social Locker and WordPress Social Share And Social Locker versions up to 1.4.2.
CVE-2025-31911 describes an SQL Injection vulnerability that allows attackers to exploit improper neutralization of special elements in SQL commands.
Yes, if exploited, CVE-2025-31911 can result in unauthorized access to sensitive data through SQL injection.